Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration Security & Risk Analysis

wordpress.org/plugins/amazingaffiliates

Monetize your Amazon Affiliate Income with Amazon API Integration & Amazon Product Blocks!

700 active installs v1.0.15.11 PHP + WP 6.0+ Updated Apr 6, 2026
amazon-affiliateamazon-affiliate-pluginamazon-associatemonetize
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration Safe to Use in 2026?

Generally Safe

Score 100/100

Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "amazingaffiliates" plugin v1.0.15.9 demonstrates a mixed security posture. On the positive side, it exhibits strong practices regarding SQL queries, utilizing prepared statements exclusively, and has excellent output escaping, with 99% of its 551 outputs properly escaped. The plugin also successfully implements nonce checks on 7 occasions and capability checks twice, indicating an awareness of common WordPress security measures. Furthermore, its vulnerability history is clean, with no recorded CVEs, which is a significant positive indicator of its security development lifecycle.

However, a major concern is the plugin's substantial attack surface, particularly the 8 AJAX handlers that lack authentication checks. This represents a significant weakness, as these handlers can be directly invoked by unauthenticated users, potentially leading to unintended actions or information disclosure. While taint analysis did not reveal any critical or high severity flows, the absence of authorization on numerous entry points presents a clear risk that could be exploited if malicious input were to be processed. The presence of the Freemius v1.0 bundled library also warrants attention, as older versions of bundled libraries can sometimes harbor known vulnerabilities, though no specific issues were flagged in this analysis.

In conclusion, the plugin has made commendable efforts in secure coding practices related to data handling and output. Nevertheless, the unprotected AJAX endpoints are a critical vulnerability that overshadows these strengths. The lack of historical vulnerabilities is reassuring, but it does not negate the present risks identified in the code analysis. Addressing the unprotected AJAX handlers should be the top priority for improving the plugin's security.

Key Concerns

  • 8 unprotected AJAX handlers
  • Bundled outdated library (Freemius v1.0)
Vulnerabilities
None known

Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration Release Timeline

v1.0.15.11Current
v1.0.15.10
v1.0.15.9
v1.0.15.8
v1.0.15.7
v1.0.15.6
v1.0.15.5
v1.0.15.4
v1.0.15.3
v1.0.15.2
v1.0.15.1
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
Code Analysis
Analyzed Mar 16, 2026

Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
544 escaped
Nonce Checks
7
Capability Checks
2
File Operations
0
External Requests
6
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

99% escaped551 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
<api_test> (admin\partials\api_test.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration Attack Surface

Entry Points9
Unprotected8

AJAX Handlers 8

authwp_ajax_product_displayincludes\class-amazingaffiliates.php:159
authwp_ajax_product_deleteincludes\class-amazingaffiliates.php:160
authwp_ajax_product_updateincludes\class-amazingaffiliates.php:161
authwp_ajax_product_createincludes\class-amazingaffiliates.php:162
authwp_ajax_force_update_cycleincludes\class-amazingaffiliates.php:164
authwp_ajax_total_updateincludes\class-amazingaffiliates.php:165
authwp_ajax_amazingaffiliates_api_force_new_tokenincludes\class-amazingaffiliates.php:174
authwp_ajax_test_apiincludes\class-amazingaffiliates.php:187

Shortcodes 1

[amazingaffiliates_product] public\class-amazingaffiliates-public.php:71
WordPress Hooks 35
actionadmin_initadmin\class-amazingaffiliates-admin.php:151
filteradmin_footer_textadmin\class-amazingaffiliates-admin.php:152
actionadmin_initadmin\class-amazingaffiliates-admin.php:664
actionadmin_initadmin\class-amazingaffiliates-admin.php:739
actionplugins_loadedincludes\class-amazingaffiliates.php:99
actioninitincludes\class-amazingaffiliates.php:110
actionadd_meta_boxesincludes\class-amazingaffiliates.php:111
actionsave_postincludes\class-amazingaffiliates.php:112
actioninitincludes\class-amazingaffiliates.php:116
actioninitincludes\class-amazingaffiliates.php:117
actioninitincludes\class-amazingaffiliates.php:118
actioninitincludes\class-amazingaffiliates.php:120
actionadmin_enqueue_scriptsincludes\class-amazingaffiliates.php:133
actionadmin_enqueue_scriptsincludes\class-amazingaffiliates.php:134
actioninitincludes\class-amazingaffiliates.php:137
actioninitincludes\class-amazingaffiliates.php:138
actioninitincludes\class-amazingaffiliates.php:140
actionamazingaffiliates_navbarincludes\class-amazingaffiliates.php:143
actionamazingaffiliates_setupnoticeincludes\class-amazingaffiliates.php:146
actionadmin_menuincludes\class-amazingaffiliates.php:149
actionamazingaffiliates_dashboardincludes\class-amazingaffiliates.php:150
actionadmin_menuincludes\class-amazingaffiliates.php:156
actionadmin_menuincludes\class-amazingaffiliates.php:158
actioninitincludes\class-amazingaffiliates.php:170
actionamazingaffiliates_api_get_the_tokenincludes\class-amazingaffiliates.php:173
actionamazingaffiliates_is_debugger_modeincludes\class-amazingaffiliates.php:177
actionadmin_menuincludes\class-amazingaffiliates.php:180
actionadmin_menuincludes\class-amazingaffiliates.php:183
actionadmin_menuincludes\class-amazingaffiliates.php:186
actioncron_schedulesincludes\class-amazingaffiliates.php:190
actionamazingaffiliates_product_update_cronincludes\class-amazingaffiliates.php:191
filterblock_categories_allpublic\class-amazingaffiliates-public.php:103
filterthe_contentpublic\class-amazingaffiliates-public.php:222
filterthe_titlepublic\class-amazingaffiliates-public.php:229
filterthe_contentpublic\class-amazingaffiliates-public.php:256

Scheduled Events 1

amazingaffiliates_product_update_cron
Maintenance & Trust

Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 6, 2026
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings3
Active installs700
Developer Profile

Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration Developer Profile

pizza2mozzarella

2 plugins · 710 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amazingaffiliates/admin/css/amazingaffiliates-admin.css/wp-content/plugins/amazingaffiliates/admin/js/amazingaffiliates-admin.js/wp-content/plugins/amazingaffiliates/admin/js/amazingaffiliates-admin-workshop.js/wp-content/plugins/amazingaffiliates/admin/js/amazingaffiliates-admin-warehouse.js/wp-content/plugins/amazingaffiliates/admin/js/amazingaffiliates-admin-settings.js
Script Paths
/wp-content/plugins/amazingaffiliates/admin/js/amazingaffiliates-admin.js/wp-content/plugins/amazingaffiliates/admin/js/amazingaffiliates-admin-workshop.js/wp-content/plugins/amazingaffiliates/admin/js/amazingaffiliates-admin-warehouse.js/wp-content/plugins/amazingaffiliates/admin/js/amazingaffiliates-admin-settings.js
Version Parameters
amazingaffiliates/style.css?ver=amazingaffiliates-admin.css?ver=amazingaffiliates-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
amazingaffiliates-admin-styles
Data Attributes
data-prefix="amazing"
JS Globals
amazingaffiliates_fsamazingaffiliates_fsamazingaffiliates_fsamazingaffiliates_fs
FAQ

Frequently Asked Questions about Amazing Affiliates – Toolkit for Amazon Associates with Amazon Product Blocks and Amazon PAAPI5 / Creators API integration